CVE-2020-9291: FortiClient for Windows Insecure Temporary File vulnerability
An Insecure Temporary File (CWE-377) vulnerability in FortiClient for Windows may allow a local user to gain elevated privileges via exhausting the pool of temporary file names combined with a symbolic link attack.
Other sources
An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a local user to gain elevated privileges via exhausting the pool of temporary file names combined with a symbolic link attack.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-9291.
What is the severity level of CVE-2020-9291?
The severity level of CVE-2020-9291 is high with a score of 7.8.
Which version of FortiClient for Windows is affected by CVE-2020-9291?
FortiClient for Windows versions 6.2.1 and below are affected by CVE-2020-9291.
How can a local user exploit CVE-2020-9291?
A local user can exploit CVE-2020-9291 by exhausting the pool of temporary file names combined with a symbolic link attack.
Are there any fixes or patches available for CVE-2020-9291?
Yes, Fortinet has released a security advisory with fixes for CVE-2020-9291. It is recommended to update to the latest version of FortiClient for Windows to mitigate the vulnerability.